Total CVEs

126,186

Critical Severity

2,292

High Severity

7,951

Last 7 Days

1,205
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 601 - 620 of 22,591 CVEs
CVE-2026-7466 HIGH - 8.8

AgentFlow contains an arbitrary code execution vulnerability that allows attackers to execute local Python pipeline files by supplying a user-controlled pipeline_path parameter to the POST /api/runs and POST /api/runs/validate endpoints. Attackers can induce requests to the local AgentFlow API to lo...

Published: Apr 29, 2026
Source: NVD
CVE-2026-7439 MEDIUM - 4.4

AgentFlow's local web API accepts non-JSON content types on POST /api/runs and POST /api/runs/validate endpoints without enforcing application/json validation, allowing attackers to bypass trust-boundary enforcement on sensitive operations. Attackers can exploit this content-type validation wea...

Published: Apr 29, 2026
Source: NVD
CVE-2026-7424 HIGH - 8.1

Integer underflow in the DHCPv6 sub-option parser in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adjacent network actor to corrupt the device's IPv6 address assignment, DNS configuration, and lease times, and to cause a denial of service (permanent IP task freeze requiring hardware res...

Published: Apr 29, 2026
Source: NVD
CVE-2026-7423 MEDIUM - 5.3

Integer underflow in the ICMP and ICMPv6 echo reply handlers in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adjacent network user to cause a denial of service (device crash) when outgoing ping support is enabled, because header sizes are subtracted from a packet length field without validat...

Published: Apr 29, 2026
Source: NVD
CVE-2026-7422 MEDIUM - 6.5

Insufficient packet validation in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to bypass all checksum and minimum-size validation by spoofing the Ethernet source MAC address to match one of the device's own registered endpoints, because the loopback detection mech...

Published: Apr 29, 2026
Source: NVD
CVE-2026-7398 HIGH - 7.3

A weakness has been identified in florensiawidjaja BioinfoMCP up to 7ada7918b9e515604d3c0ae264d3a9af10bf6e54. This vulnerability affects the function Upload of the file bioinfo_mcp_platform/app.py of the component Upload Endpoint. This manipulation of the argument Name causes path traversal. The att...

Published: Apr 29, 2026
Source: NVD
CVE-2026-7397 MEDIUM - 4.4

A security flaw has been discovered in NousResearch hermes-agent 0.8.0. This affects the function _check_sensitive_path of the file tools/file_tools.py. The manipulation results in symlink following. Attacking locally is a requirement. The exploit has been released to the public and may be used for ...

Published: Apr 29, 2026
Source: NVD
CVE-2026-41499 MEDIUM - 6.5

Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.0.0 to before version 4.14.4, multiple heap-based out-of-bounds WRITE vulnerabilities exist in parse_uname_string() (remoted_op.c). This function processes OS identification data from agents ...

Vendor: wazuh
Product: wazuh
Published: Apr 29, 2026
Source: NVD
CVE-2026-30893 CRITICAL - 9.0

Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.4.0 to before version 4.14.4, a path traversal vulnerability in Wazuh's cluster synchronization extraction routine allows an authenticated cluster peer to write arbitrary files outside t...

Vendor: wazuh
Product: wazuh
Published: Apr 29, 2026
Source: NVD
CVE-2026-28221 MEDIUM - 6.5

Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.8.0 to before version 4.14.4, a stack-based buffer overflow exists in print_hex_string() in wazuh-remoted. The bug is triggered when formatting attacker-controlled bytes using sprintf(dst_buf...

Vendor: wazuh
Product: wazuh
Published: Apr 29, 2026
Source: NVD
CVE-2026-27105 MEDIUM - 6.3

Dell/Alienware Purchased Apps, versions prior to 1.1.31.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Arbitrary File Write

Vendor: Dell
Product: Dell/Alienware Purchased Apps
Published: Apr 29, 2026
Source: NVD
CVE-2026-26206 MEDIUM - 6.5

Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.0.0 to before version 4.14.4, Wazuh's server API brute-force protection for POST /security/user/authenticate can be bypassed by sending concurrent authentication requests. Although the c...

Vendor: wazuh
Product: wazuh
Published: Apr 29, 2026
Source: NVD
CVE-2026-41483 MEDIUM - 5.9

OpenTelemetry.Resources.Azure has an unbounded HTTP response body read

Vendor: nuget
Product: OpenTelemetry.Resources.Azure
Published: Apr 29, 2026
Source: GitHub

beets has a Cross-site Scripting vulnerability

Vendor: pip
Product: beets
Published: Apr 29, 2026
Source: GitHub
CVE-2026-7396 MEDIUM - 5.3

A vulnerability was identified in NousResearch hermes-agent 0.8.0. Affected by this issue is some unknown functionality of the file gateway/platforms/wecom.py of the component WeChat Work Platform Adapter. The manipulation leads to path traversal. It is possible to initiate the attack remotely. The ...

Published: Apr 29, 2026
Source: NVD
CVE-2026-7394 MEDIUM - 4.7

A vulnerability was determined in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/view_order.php of the component GET Parameter Handler. Executing a manipulation of the argument ID can lead to sql injection. The attack may be...

Published: Apr 29, 2026
Source: NVD
CVE-2026-5712 HIGH - 8.0

This vulnerability impacts all versions of IdentityIQ and allows an authenticated identity that is the requestor or assignee of a work item to edit the definition of a role without having an assigned capability that would allow role editing.

Published: Apr 29, 2026
Source: NVD
CVE-2026-26204 MEDIUM - 4.4

Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 1.0.0 to before version 4.14.4, a heap-based out-of-bounds WRITE occurs in GetAlertData, resulting in writing a NULL byte exactly 1 byte before the start of the buffer allocated by strdup. Due ...

Vendor: wazuh
Product: wazuh
Published: Apr 29, 2026
Source: NVD
CVE-2026-26015 CRITICAL - 9.8

DocsGPT is a GPT-powered chat for documentation. From version 0.15.0 to before version 0.16.0, an attacker accessing both the official DocsGPT website or any local and public deployment, can craft a malicious payload bypassing the "MCP test" behavior to achieve arbitrary remote code execut...

Vendor: arc53
Product: DocsGPT
Published: Apr 29, 2026
Source: NVD
CVE-2026-7393 MEDIUM - 4.7

A vulnerability was found in SourceCodester Pizzafy Ecommerce System 1.0. Affected is the function save_menu of the file /admin/admin_class_novo.php of the component File Extension Handler. Performing a manipulation of the argument img results in unrestricted upload. The attack is possible to be car...

Published: Apr 29, 2026
Source: NVD